Bug 963633 (CVE-2016-1931) - VUL-0: CVE-2016-1931: MozillaFirefox: Memory safety bugs fixed in Firefox 44
Summary: VUL-0: CVE-2016-1931: MozillaFirefox: Memory safety bugs fixed in Firefox 44
Status: RESOLVED FIXED
Alias: CVE-2016-1931
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: All openSUSE 42.1
: P3 - Medium : Critical
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on: 963520
Blocks:
  Show dependency treegraph
 
Reported: 2016-01-26 18:06 UTC by Andreas Stieger
Modified: 2020-04-05 18:20 UTC (History)
6 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2016-01-26 18:06:12 UTC
https://www.mozilla.org/en-US/security/advisories/mfsa2016-01/

Mozilla developers and community identified and fixed several memory safety bugs in the browser engine used in Firefox and other Mozilla-based products. Some of these bugs showed evidence of memory corruption under certain circumstances, and we presume that with enough effort at least some of these could be exploited to run arbitrary code. 

Bob Clary, Carsten Book, Christian Holler, Nicolas Pierron, Eric Rescorla, Tyson Smith, Gabor Krizsanits, and Randell Jesup reported memory safety problems and crashes that affect Firefox 43.

References:
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1229825,1231121,1180064,1186973,1206675,1209546,1209368,1209366,1209365,1209358,1207298,1222015,1234576

openSUSE only.
Comment 1 Swamp Workflow Management 2016-01-26 23:00:15 UTC
bugbot adjusting priority
Comment 2 Andreas Stieger 2016-01-27 10:40:34 UTC
openSUSE update is running
Comment 3 Andreas Stieger 2016-02-01 21:26:24 UTC
Releasing updates for openSUSE only bugs.
Comment 4 Swamp Workflow Management 2016-02-02 01:12:33 UTC
openSUSE-SU-2016:0309-1: An update that fixes 14 vulnerabilities is now available.

Category: security (important)
Bug References: 963633,963634,963635,963637,963641,963643,963644,963645,963731
CVE References: CVE-2015-7208,CVE-2016-1930,CVE-2016-1931,CVE-2016-1933,CVE-2016-1935,CVE-2016-1937,CVE-2016-1938,CVE-2016-1939,CVE-2016-1942,CVE-2016-1943,CVE-2016-1944,CVE-2016-1945,CVE-2016-1946,CVE-2016-1947
Sources used:
openSUSE Leap 42.1 (src):    MozillaFirefox-44.0-12.2, mozilla-nspr-4.11-7.1, mozilla-nss-3.21-9.1
openSUSE 13.2 (src):    MozillaFirefox-44.0-59.1, mozilla-nspr-4.11-12.1, mozilla-nss-3.21-25.1